From d9ee7dd3b35f78a7adc8fcd15fa6afa25f744638 Mon Sep 17 00:00:00 2001 From: dannyrb Date: Sat, 4 May 2019 21:50:53 -0400 Subject: [PATCH] second config --- docker/authproxy/config/nginx.conf | 325 +++++++++++++++++++++++++++++ 1 file changed, 325 insertions(+) create mode 100644 docker/authproxy/config/nginx.conf diff --git a/docker/authproxy/config/nginx.conf b/docker/authproxy/config/nginx.conf new file mode 100644 index 000000000..68f4ef951 --- /dev/null +++ b/docker/authproxy/config/nginx.conf @@ -0,0 +1,325 @@ +## Best: https://edhull.co.uk/blog/2018-06-06/keycloak-nginx +## +## + +worker_processes 2; ## Default: 1 +error_log /var/log/nginx/error.log; +pid /var/run/nginx.pid; +# Load dynamic modules. See /usr/share/doc/nginx/README.dynamic. +include /usr/share/nginx/modules/*.conf; + +events { + # 4096? + worker_connections 1024; ## Default: 1024 + use epoll; # + multi_accept on; # +} + +http { + # + include mime.types; + default_type application/octet-stream; + keepalive_timeout 65; + keepalive_requests 100000; + tcp_nopush on; + tcp_nodelay on; + + # lua_ settings + # + lua_package_path '/usr/local/openresty/lualib/?.lua;;'; + # lua_package_path '/opt/openresty/lualib/?.lua;;'; + # lua_package_path '/usr/local/share/lua/5.3/?.lua;;'; + lua_shared_dict discovery 1m; # cache for discovery metadata documents + lua_shared_dict jwks 1m; # cache for JWKs + # lua_ssl_trusted_certificate /etc/ssl/certs/ca-certificates.crt; + + variables_hash_max_size 2048; + server_names_hash_bucket_size 128; + server_tokens off; + + resolver 8.8.8.8 valid=30s ipv6=off; + resolver_timeout 11s; + + log_format main 'hi $remote_addr - $remote_user [$time_local] "$request" ' + '$status $body_bytes_sent "$http_referer" ' + '"$http_user_agent" "$http_x_forwarded_for"'; + + # recommended by other + # include /etc/nginx/conf.d/*.conf; + # index index.html index.htm; + + # No idea what this is doing + # https://stackoverflow.com/a/5877989/1867984 + # upstream upstream_server { + # # server 10.100.4.200:1010 max_fails=3 fail_timeout=30s; + # server 127.0.0.1: + # } + + # Nginx `listener` block per keycloak client + server { + # old + # listen 80 default_server; + # listen [::]:80 default_server; + + listen 80 default_server; + # listen 443 ssl; + # Domain to protect + server_name localhost 127.0.0.1; # mydomain.co.uk; + proxy_intercept_errors off; + # ssl_certificate /etc/letsencrypt/live/mydomain.co.uk/fullchain.pem; + # ssl_certificate_key /etc/letsencrypt/live/mydomain.co.uk/privkey.pem; + server_tokens off; + + # access_log logs/mydomain.log; + access_log /var/log/nginx/test.com.access.log; + error_log logs/mydomain.error.log; + + root /var/www/html; + index index.html index.htm; + + lua_code_cache off; + # There is a bug I found with sessions not sticking properly and causing spontaneous 403's + # For now, set the session secret hard-coded + # set $session_secret 723p4hR234t36VsCD8g565325IC0022G; + + gzip on; + gzip_types text/css application/javascript application/json image/svg+xml; + gzip_comp_level 9; + etag on; + + # Single Page App + # Try files, fallback to index.html + # + location / { + try_files $uri $uri/ /index.html; + } + + # DO NOT CACHE + # This is where we would pick up on a new version/service-worker + # + location /index.html { + add_header Cache-Control no-cache; + } + + # [PROTECTED] Reverse Proxy for `orthanc` + # + location /pacs/ { + + # Configure auth + # https://github.com/zmartzone/lua-resty-openidc + # https://gist.github.com/alhafoudh/e87392ee60cf14bb33962847f5a84b24 + # https://www.jerney.io/secure-apis-kong-keycloak-1/ + set $session_check_ssi off; + set $session_secret Eeko7aeb6iu5Wohch9Loo1aitha0ahd1; + set $session_storage cookie; + + access_by_lua_block { + local opts = { + redirect_uri = "http://127.0.0.1/callback", + discovery = "http://127.0.0.1/auth/realms/master/.well-known/openid-configuration", + client_id = "pacs", + client_secret = "cd2b3a3c-a6c6-4a37-a15d-b2e5598735b6" + } + + local res, err = require("resty.openidc").authenticate(opts) + + if err then + ngx.status = 200 + ngx.print(err) + ngx.log(ngx.ERR, err) + ngx.say(err) + ngx.exit(ngx.HTTP_INTERNAL_SERVER_ERROR) + end + + ngx.req.set_header("X-User", res.id_token.sub) + } + + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $remote_addr; + proxy_set_header Host $host; + + expires 0; + add_header Cache-Control private; + + proxy_pass http://orthanc:8042/; + } + + + # [UNPROTECTED] reverse proxy for `orthanc` + # + # location /pacs/ { + # proxy_set_header X-Real-IP $remote_addr; + # proxy_set_header X-Forwarded-For $remote_addr; + # proxy_set_header Host $host; + # + # proxy_pass http://orthanc:8042/; + # + # # OR + # # rewrite ^/pacs(.*) /$1 break; + # # proxy_pass http://orthanc:8042; + # } + + + # location /pacs-protected/ { + + # # Configure auth + # access_by_lua ' + # local opts = { + # redirect_uri_path = "/pacs-protected/redirect_uri", + # accept_none_alg = true, + # discovery = "http://localhost:8080/auth/realms/internal/.well-known/openid-configuration", + # client_id = "pacs", + # client_secret = "ba0ea97a-765a-4bf0-a693-7059938f3229", + # ssl_verify = "no", + # redirect_uri_scheme = "http", + # logout_path = "/logout", + # redirect_after_logout_uri = "http://localhost:8080/auth/realms/internal/protocol/openid-connect/logout", + # redirect_after_logout_with_id_token_hint = false, + # session_contents = {id_token=true} + # } + + # local res, err = require("resty.openidc").authenticate(opts) + + # if err then + # ngx.status = 403 + # ngx.say(err) + # ngx.exit(ngx.HTTP_FORBIDDEN) + # end + # '; + + # proxy_set_header X-Real-IP $remote_addr; + # proxy_set_header X-Forwarded-For $remote_addr; + # proxy_set_header Host $host; + + # expires 0; + # add_header Cache-Control private; + + # proxy_pass http://orthanc:8042/; + # } + + # Keycloak + # + location /auth/ { + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header Host $http_host; + + proxy_pass http://keycloak:8080/auth/; + } + + # Set `keycloak_endpoint` + # Use `client_id` and `client_secret` generate in keycloak + # access_by_lua ' + # local opts = { + # redirect_uri_path = "/redirect_uri", + # accept_none_alg = true, + # discovery = "https://keycloak_endpoint/auth/realms/internal_applications/.well-known/openid-configuration", + # client_id = "elk", + # client_secret = "!!! Set this to the secret from the JSON !!! ", + # ssl_verify = "no", + # redirect_uri_scheme = "https", + # logout_path = "/logout", + # redirect_after_logout_uri = "https://keycloak_endpoint/auth/realms/internal_applications/protocol/openid-connect/logout", + # redirect_after_logout_with_id_token_hint = false, + # session_contents = {id_token=true} + # } + # local res, err = require("resty.openidc").authenticate(opts) + + # if err then + # ngx.status = 403 + # ngx.say(err) + # ngx.exit(ngx.HTTP_FORBIDDEN) + # end + # '; + + # If the user is authenticated, then the normal nginx `proxy_pass` + # redirect will apply as normal + + # location /auth + # location / { + # if ($request_method = 'OPTIONS') { + # add_header 'Access-Control-Allow-Origin' '*'; + # add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; + # # + # # Custom headers and headers various browsers *should* be OK with but aren't + # # + # add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; + # # + # # Tell client that this pre-flight info is valid for 20 days + # # + # add_header 'Access-Control-Allow-Headers' 'Authorization'; + # add_header 'Access-Control-Allow-Credentials' true; + # add_header 'Access-Control-Max-Age' 1728000; + # add_header 'Content-Length' 0; + # return 204; + # } + # if ($request_method = 'POST') { + # add_header 'Access-Control-Allow-Origin' '*'; + # add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; + # add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; + # add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range'; + # } + # if ($request_method = 'GET') { + # add_header 'Access-Control-Allow-Origin' '*'; + # add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; + # add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; + # add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range'; + # add_header 'Access-Control-Allow-Headers' 'Authorization'; + # add_header 'Access-Control-Allow-Credentials' true; + # } + + # proxy_pass http://orthanc:8042; + # # proxy_pass http://upstream_server; + # # proxy_http_version 1.1; + + # # proxy_set_header Host $host; + # # proxy_set_header X-Real-IP $remote_addr; + # # proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + # # proxy_set_header X-Forwarded-Proto $scheme; + # } + + + + # discover & redirect_after_logout_uri + # are hitting keycloak (replace localhost:8888 with host, anmd use correct protocol) + # access_by_lua ' + # local opts = { + # redirect_uri_path = "/", + # discovery = "http://localhost:8888/auth/realms/master/.well-known/openid-configuration", + # client_id = "clientID", + # client_secret = "clientSecret", + # redirect_uri_scheme = "https", + # logout_path = "/logout", + # redirect_after_logout_uri = "http://localhost:8888/auth/realms/master/protocol/openid-connect/logout?redirect_uri=http%3A%2F%2Fianbull.com", + # redirect_after_logout_with_id_token_hint = false, + # session_contents = {id_token=true} + # } + # -- call introspect for OAuth 2.0 Bearer Access Token validation + # local res, err = require("resty.openidc").authenticate(opts) + # if err then + # ngx.status = 403 + # ngx.say(err) + # ngx.exit(ngx.HTTP_FORBIDDEN) + # end + # '; + + # I disbled caching so the browser won't cache the site. + # expires 0; + # add_header Cache-Control private; + + # location / { + # } + + # redirect server error pages to the static page /40x.html + # + # error_page 404 /404.html; + # location = /40x.html { + # } + + # redirect server error pages to the static page /50x.html + # + # error_page 500 502 503 504 /50x.html; + # location = /50x.html { + # } + } +}